CVE-2009-2167
EgyPlus 7ammel < 1.0.1 - SQL Injection via Username or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2167. PoCs published by Qabandi.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in EgyPlus 7ml <= 1.0.1, allowing authentication bypass via manipulated cookie or POST data. The vulnerability arises from unsanitized user input in the login process.
Description
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in EgyPlus 7ml <= 1.0.1, allowing authentication bypass via manipulated cookie or POST data. The vulnerability arises from unsanitized user input in the login process.